CVE-2024-32354: Command Injection
Published May 14, 2024
·Updated
TOTOLINK X5000R V9.1.0cu.2350B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
Affected Software
3 affected components
TOTOLINK X5000R=V9.1.0cu.2350_B20230313
All of the following
TOTOLINK X5000r Firmware=9.1.0cu.2350_b20230313
TOTOLINK X5000R
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·04:17 PM
Aug 2, 2024
Data Sourced
via MITRE·02:13 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-32354?
CVE-2024-32354 is classified with a high severity due to its potential for command injection.
2
How do I fix CVE-2024-32354?
To mitigate CVE-2024-32354, update the firmware of the TOTOLINK X5000R to a version that addresses the vulnerability.
3
What systems are affected by CVE-2024-32354?
CVE-2024-32354 affects the TOTOLINK X5000R with firmware version V9.1.0cu.2350_B20230313.
4
Can CVE-2024-32354 allow remote exploitation?
Yes, CVE-2024-32354 can potentially allow remote exploitation through command injection.
5
What steps can I take to protect my network from CVE-2024-32354?
To protect against CVE-2024-32354, ensure your TOTOLINK X5000R device is updated and consider disabling unused features.